Monday, August 3, 2026

Compute & Cloud

Critical Cisco bug allows persistent network access since 2023

Cisco is warning of a critical vulnerability in its Catalyst SD-WAN products that has allowed hackers to maintain persistent, hidden network access for at least three years.

Critical Cisco bug allows persistent network access since 2023

Cisco has disclosed a critical vulnerability in its Catalyst SD-WAN products—a networking product used by large enterprises to connect private networks over long distances. According to Cisco, hackers have been actively exploiting this security flaw since 2023. The bug carries a maximum-rated vulnerability severity score of 10.0, which allows remote attackers to break into networks over the internet. Once inside, hackers can gain the highest level of permissions on these devices, enabling them to maintain persistent hidden access to spy on systems or steal data. Cisco researchers traced evidence of this exploitation back at least three years.

The discovery has prompted regulatory action in the United States. The Cybersecurity and Infrastructure Security Agency (CISA), the US federal cybersecurity agency, has ordered all civilian federal agencies to patch their systems by end-of-day Friday. In its directive, CISA cited an imminent threat and unacceptable risk to the federal government’s systems. The agency noted that it is aware of ongoing active exploitation of the vulnerability.

The threat is not limited to US federal networks. Government agencies in several countries—including Australia, Canada, New Zealand, the United Kingdom, and the United States—have issued joint warnings that threat actors are targeting organizations globally. While neither Cisco nor the participating governments have officially attributed the attacks to a specific nation-state or known threat group, security researchers are tracking one distinct cluster of this activity under the identifier UAT-8616.

Among the targets, Cisco noted that some affected organizations are classified as “critical infrastructure.” While the company did not name specific victims, this designation typically covers essential public services such as power grids, water supply systems, and transportation networks. This incident follows a previous warning from Cisco in December regarding a similarly rated 10.0 vulnerability that was actively used to hack into customer networks.

Why it matters

This vulnerability highlights the persistent risk to critical infrastructure when networking hardware is compromised, forcing government intervention to secure essential systems against long-term unauthorized access.